Legal
Privacy statement
What ATON BV does with personal data, and what you can ask us to do about it.
Last updated 22 August 2026.
Who is responsible
ATON BV is the controller for the personal data described here.
ATON BV
Willem de Zwijgerlaan 350, 1055 RD Amsterdam, Netherlands
Chamber of Commerce (KvK) 72184949
[email protected] · +31 6 15555560
What we collect, and why
| Data | Where it comes from | Why we have it | Legal basis |
|---|---|---|---|
| Name, organisation, email address, country, subject of enquiry, and whatever you write in the message | The enquiry form on this site, or an email, call or message you send us directly | To answer your enquiry and, where it leads somewhere, to discuss and deliver a project | Steps taken at your request before entering a contract, and our legitimate interest in responding to business enquiries |
| Business contact details and correspondence | You, or a colleague of yours, in the course of a project | To perform the contract and keep a record of what was agreed | Performance of a contract; legitimate interest in an accurate record |
| Technical log data — IP address, request time, page requested, user agent | Automatically, by our hosting provider, when your browser requests a page | To serve the site, and to keep it secure and available | Legitimate interest in operating and securing the site |
The enquiry form does not send data to us over the internet. By default it opens a message in your own email application with the details you entered, which you then choose to send. Nothing leaves your device unless you press send in your mail client.
What we do not do
- We set no cookies and run no analytics, advertising or tracking scripts. See the cookie statement.
- We do not buy, sell, rent or trade personal data.
- We do not use your data for automated decision-making or profiling.
- We do not send marketing email to people who have not asked for it.
Who else sees it
Only parties who need to, and only for the purposes above:
- Our hosting provider — DigitalOcean, which serves this website and processes the technical log data described above.
- Our email and office providers — who process the correspondence in which your enquiry is held.
- Project partners — where delivering what you asked for requires it, for example a manufacturer preparing a quotation, a training venue, or a freight and customs agent. We share the minimum needed, and we tell you when we do.
- Advisers and authorities — where we are required by law, or need advice on a legal claim.
These parties act as processors on our instructions, under a data processing agreement, except where they are independent controllers in their own right (for example a customs authority).
Transfers outside the EEA
We work in Egypt, North Africa and the Gulf, and some of our providers are established outside the European Economic Area. Where personal data is transferred outside the EEA, we rely on an adequacy decision of the European Commission where one exists, and otherwise on the Commission's Standard Contractual Clauses together with any additional measures the transfer requires.
How long we keep it
- Enquiries that go nowhere — up to 24 months from the last contact, so we recognise you if you write again.
- Project and client records — for the duration of the relationship and then 7 years, which is the retention period Dutch tax law requires for administration.
- Technical log data — the retention period applied by our hosting provider, typically a matter of weeks.
Your rights
Under the General Data Protection Regulation you may ask us to:
- give you a copy of the personal data we hold about you (access);
- correct data that is wrong or incomplete (rectification);
- delete data we no longer have a reason to keep (erasure);
- restrict how we use it, or object to our use of it where we rely on legitimate interest;
- send you, or another organisation, a machine-readable copy of data you gave us (portability);
- withdraw consent, where we relied on consent — which does not affect what we did before you withdrew it.
Write to [email protected]. We answer within one month. We may ask you to confirm your identity first, so that we do not hand your data to somebody else.
Complaints
If you think we have handled your data badly, tell us and we will try to put it right. You also have the right to complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or to the supervisory authority where you live or work.
Security
This site is served over HTTPS. Access to our email and project records is restricted to the people who need it and protected by multi-factor authentication. No system is perfect; if we suffer a breach that presents a risk to you, we will notify you and the supervisory authority as the GDPR requires.
Changes
If we change how we handle personal data — for example by adding a server-side contact form or an analytics tool — we will update this statement and change the date at the top before the change takes effect.